CVE-2012-5855

Publication date 10 July 2013

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

The SHAddToRecentDocs function in VideoLAN VLC media player 2.0.4 and earlier might allow user-assisted attackers to cause a denial of service (crash) via a crafted file name that triggers an incorrect string-length calculation when the file is added to VLC. NOTE: it is not clear whether this issue crosses privilege boundaries or whether it can be exploited without user interaction.

Read the notes from the security team

Status

Package Ubuntu Release Status
vlc 14.10 utopic Ignored
14.04 LTS trusty Ignored
13.10 saucy Ignored end of life
13.04 raring Ignored end of life
12.10 quantal Ignored end of life
12.04 LTS precise Ignored
11.10 oneiric Ignored end of life
10.04 LTS lucid Ignored end of life
8.04 LTS hardy Ignored end of life

Notes


mdeslaur

not security relevant